The Hacker News·4 min read·hard

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

T
The Hacker News
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
AI Summary

Cybersecurity researchers have identified a new post-exploitation toolkit called PEEP that disguises itself as a browser extension to compromise Chrome and Edge. The malware allows attackers to execute host-level commands and exfiltrate sensitive user data.

Why it matters

This highlights a sophisticated threat vector targeting browser security, potentially exposing users to remote access and credential theft.

Dive DeeperCreate a free account to unlock

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.

"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences integrity values," SOCRadar said . "A native-messaging tool then extends it beyond browser telemetry to host-level command execution and file management."

Once installed, the PEEP "extension" agent polls its command-and-control (C2) server ("206.237.30[.]232" or " xfjcc[.]fun ") every 30 seconds over plaintext HTTP for new commands, while exfiltrating browsing history, active-tab metadata, and session cookies. It also functions as a remote access and browser monitoring toolkit that runs host commands, steals credentials, hijacks sessions, and alters web pages.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologybusiness

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in